Gentoo Archives: gentoo-announce

From: Robert Buchholz <rbu@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200805-07 ] Linux Terminal Server Project: Multiple vulnerabilities
Date: Fri, 09 May 2008 14:31:10
Message-Id: 200805091624.19240.rbu@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200805-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Linux Terminal Server Project: Multiple vulnerabilities
9 Date: May 09, 2008
10 Bugs: #215699
11 ID: 200805-07
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in components shipped
19 with LTSP which allow remote attackers to compromise terminal clients.
20
21 Background
22 ==========
23
24 The Linux Terminal Server Project adds thin-client support to Linux
25 servers.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-misc/ltsp < 5.0 Vulnerable!
34 -------------------------------------------------------------------
35 NOTE: Certain packages are still vulnerable. Users should migrate
36 to another package if one is available or wait for the
37 existing packages to be marked stable by their
38 architecture maintainers.
39
40 Description
41 ===========
42
43 LTSP version 4.2, ships prebuilt copies of programs such as the Linux
44 Kernel, the X.org X11 server (GLSA 200705-06, GLSA 200710-16, GLSA
45 200801-09), libpng (GLSA 200705-24, GLSA 200711-08), Freetype (GLSA
46 200705-02, GLSA 200705-22) and OpenSSL (GLSA 200710-06, GLSA 200710-30)
47 which were subject to multiple security vulnerabilities since 2006.
48 Please note that the given list of vulnerabilities might not be
49 exhaustive.
50
51 Impact
52 ======
53
54 A remote attacker could possibly exploit vulnerabilities in the
55 aforementioned programs and execute arbitrary code, disclose sensitive
56 data or cause a Denial of Service within LTSP 4.2 clients.
57
58 Workaround
59 ==========
60
61 There is no known workaround at this time.
62
63 Resolution
64 ==========
65
66 LTSP 4.2 is not maintained upstream in favor of version 5. Since
67 version 5 is not yet available in Gentoo, the package has been masked.
68 We recommend that users unmerge LTSP:
69
70 # emerge --unmerge net-misc/ltsp
71
72 If you have a requirement for Linux Terminal Servers, please either set
73 up a terminal server by hand or use one of the distributions that
74 already migrated to LTSP 5. If you want to contribute to the
75 integration of LTSP 5 in Gentoo, or want to follow its development,
76 find details in bug 177580.
77
78 References
79 ==========
80
81 [ 1 ] GLSA 200705-02
82 http://www.gentoo.org/security/en/glsa/glsa-200705-02.xml
83 [ 2 ] GLSA 200705-06
84 http://www.gentoo.org/security/en/glsa/glsa-200705-06.xml
85 [ 3 ] GLSA 200705-22
86 http://www.gentoo.org/security/en/glsa/glsa-200705-22.xml
87 [ 4 ] GLSA 200705-24
88 http://www.gentoo.org/security/en/glsa/glsa-200705-24.xml
89 [ 5 ] GLSA 200710-06
90 http://www.gentoo.org/security/en/glsa/glsa-200710-06.xml
91 [ 6 ] GLSA 200710-16
92 http://www.gentoo.org/security/en/glsa/glsa-200710-16.xml
93 [ 7 ] GLSA 200710-30
94 http://www.gentoo.org/security/en/glsa/glsa-200710-30.xml
95 [ 8 ] GLSA 200711-08
96 http://www.gentoo.org/security/en/glsa/glsa-200711-08.xml
97 [ 9 ] GLSA 200801-09
98 http://www.gentoo.org/security/en/glsa/glsa-200801-09.xml
99 [ 10 ] Gentoo bug 177580: Port LTSP 5 to Gentoo
100 https://bugs.gentoo.org/177580
101
102 Availability
103 ============
104
105 This GLSA and any updates to it are available for viewing at
106 the Gentoo Security Website:
107
108 http://security.gentoo.org/glsa/glsa-200805-07.xml
109
110 Concerns?
111 =========
112
113 Security is a primary focus of Gentoo Linux and ensuring the
114 confidentiality and security of our users machines is of utmost
115 importance to us. Any security concerns should be addressed to
116 security@g.o or alternatively, you may file a bug at
117 http://bugs.gentoo.org.
118
119 License
120 =======
121
122 Copyright 2008 Gentoo Foundation, Inc; referenced text
123 belongs to its owner(s).
124
125 The contents of this document are licensed under the
126 Creative Commons - Attribution / Share Alike license.
127
128 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature